Description
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0069 | The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input. |
Github GHSA |
GHSA-v899-28g4-qmh8 | XML External Entity vulnerability in Easy-XML |
References
| Link | Providers |
|---|---|
| https://github.com/darkfoxprime/python-easy_xml/issues/1 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:56:05.074Z
Reserved: 2020-10-07T00:00:00.000Z
Link: CVE-2020-26705
No data.
Status : Modified
Published: 2021-10-31T20:15:07.840
Modified: 2024-11-21T05:20:15.453
Link: CVE-2020-26705
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA